SecZen
seczen.bsky.social
SecZen
@seczen.bsky.social
I love learning and discovering new security tools.
🔒 Decrypt Weekly – November 1 Issue
Check out this week’s edition for interesting reads, security tools, and updates on key changes in the cybersecurity world. Stay connected with weekly updates! #CyberSecurity
Newsletter 1 November 2024
Get the latest security insights, tech updates, and impactful tools reviewed in our November 1, 2024, newsletter.
decrypt.lol
November 1, 2024 at 12:09 PM
🔒 Explore our guide on security architecture with threat-based modeling. Learn how integrating Time-Based Security, the Intrusion Kill Chain, and MITRE ATT&CK strengthens detection, response, and resilience against cyber threats. #CyberSecurity #ThreatModeling #SOC
Defending Against Advanced Cyber Threats
Integrating Time-Based Security, Intrusion Kill Chain, and MITRE ATT&CK
decrypt.lol
October 31, 2024 at 12:20 AM
🔗 Chainloop - software supply chains 🚀 v0.75.x Highlights:
Org membership API
Scoped invitations
Role info display in API
Set role during invitation
Read-only viewer role
Domain-based allow-listing
docs.chainloop.dev
#infosec #cybersecurity #devsecops #cicd
March 8, 2024 at 12:01 AM
mitmproxy 🚀 10.2.3 Release Highlights: Fixed IPv6 glitch, CONNECT URL bug, added arm64 macOS variant. Addressed DNS duplicates, wireguard config issue, and leaf cert creation bug. New mitmdump options and enhanced HTTP flow filters
mitmproxy.org
#infosec #cybersecurity #pentesting
March 7, 2024 at 12:56 AM
Forwarder - MITM proxy 🚀 v.1.2.0 🆕 Introducing idle timeout, armed TLS listener, and connection metrics. 🔒 Security boosts with automatic closure after 1hr of inactivity and enhanced ConnectTimeout. Added GOMEMLIMIT and GOMAXPROCS metrics. forwarder-proxy.io
#mitm #infosec #cybersecurity
March 5, 2024 at 11:23 AM
httpX - toolkit that allows running reliable multi threaded probes
#infosec #cybersecurity
github.com/projectdisco...
March 2, 2024 at 2:01 PM
Teleport - 🚀 v15.1.0 Release Highlights:
- Standalone tbot Docker image
- Custom mouse pointers for remote desktop sessions
- Okta groups and apps synchronization
- EKS auto-discovery in Access Management UI
- TLS routing native WebSocket connection upgrade support
goteleport.com
#infosec #devsecops
March 1, 2024 at 10:51 AM
Chainloop - software supply chain control plane 🚀 v0.70.0 release highlights
- support parent ID for auto-create hierarchical projects
- filter workflow runs by status
- added workflow latest_revision and description
#sbom #cicd #infosec #cybersecurity
Release v0.70.0 · chainloop-dev/chainloop
Highlights Hierarchical Dependency-Track project support @sedan07 extended the dependency-Track plugin to support attaching automatically created projects to existing parent projects. This enables ...
github.com
March 1, 2024 at 10:45 AM
Vault - secrets manager 🚀 Release v1.15.6
🔒 Ensure secure client certificate validation by comparing public keys with trusted non-CA and leaf certificates, preventing trust in certs with the same serial but different keys or use of alternate certs with forged serial numbers.
#infosec #devsecops
Vault by HashiCorp
Vault secures, stores, and tightly controls access to tokens, passwords, certificates, API keys, and other secrets critical in modern computing.
www.vaultproject.io
February 29, 2024 at 11:24 PM
Kicks - IaC vuln scanner 🚀 v1.7.13 Release Highlights:
🔄 Parallel scanning
➕ Terraform nifcloud queries
🔍 Tencentcloud: cbs disk without encryption
🔍 Various queries for CloudFormation, Docker, crossplane, pulumi, and more!
#iac #devsecops #infosec #cybersecurity
KICS - Keeping Infrastructure as Code Secure
KICS is an open source solution for static code analysis of Infrastructure as Code.
www.kics.io
February 29, 2024 at 11:15 PM
OPA - Open Policy Agent 🚀 v0.62.0 Release:
🔄 Environment variable backups for cmd flags
➕ Added WithBundleParserOpts to OCI downloader
🔍 Logging optimization
🔄 Allow bundles to contain calls to unknown Rego functions
🛠 Improved input validation in topdown/http
#infosec #cybersecurity
Open Policy Agent
Policy-based control for cloud native environments
www.openpolicyagent.org
February 29, 2024 at 10:29 PM
🔐 Kali Linux 2024.1 Release is here: ✨ Kali project got more mirrors, Theme refresh, NetHunter Updates, and introducing new tools: blue-hydra, OpenTAXII, readpe, Snort, and Above!
#pentesting #infosec #cybersecurity
Kali Linux 2024.1 Release (Micro Mirror) | Kali Linux Blog
Hello 2024! Today we are unveiling Kali Linux 2024.1. As this is our the first release of the year, it does include new visual elements! Along with this we also have some exciting new mirrors to talk ...
www.kali.org
February 29, 2024 at 2:01 AM
netmaker - wireguard based networks 🚀 v0.23.0 update: ✨ Revamped Internet Gateways: Improved connectivity for hosts and clients! 🌐 Access internet gateways via Remote Access tab. 💻 PostUp/PostDown commands, EMQX cloud support, Metadata for Remote Access Gateways.
#selfhosted #netsec #vpn #zerotrust
GitHub - gravitl/netmaker: Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks.
Netmaker makes networks with WireGuard. Netmaker automates fast, secure, and distributed virtual networks. - gravitl/netmaker
github.com
February 28, 2024 at 10:57 PM
🚀 Terrascan 1.18.12 is here! 🔍 Update includes:
✨ Fixed display line numbers in CloudFormation templates scan results.
Terrascan enhances IaC compliance and security.
#devsecops #terraform #cicd #infosec
GitHub - tenable/terrascan: Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure. - tenable/terrascan
github.com
February 27, 2024 at 10:51 PM
xca - CA certificate and key management
🚀 2.6.0 Release Highlights:
🌐 Support for ovpn files
🛠 Fixes PKCS12 imports
🔐 Support for legacy keys
#cryptography #certificates #infosec #cybersecurity
GitHub - chris2511/xca: X Certificate and Key management
X Certificate and Key management. Contribute to chris2511/xca development by creating an account on GitHub.
github.com
February 27, 2024 at 12:48 AM
HollowsHunter - scan Windows processes for malicious implants v0.3.9 release update
🚀 Added /pattern flag to allow search for custom signatures using SigFinder format
github.com/hasherezade/...
#malware #infosec #cybersecurity
February 25, 2024 at 6:00 PM
aws-firewall-factory - Web AWS firewall factory 4.2.3 Release
- Check for Managed Rule Groups Labels and Rules
- Athena WAF log table support for easy analysis
- Fixes for customizable log group creation
#netsec #infosec #cybersecruity
GitHub - globaldatanet/aws-firewall-factory: Easily improve the security of your web applications with aws firewall factory. Protect your valuable assets with seamless WAF deployment, updates, and sta...
Easily improve the security of your web applications with aws firewall factory. Protect your valuable assets with seamless WAF deployment, updates, and staging, all efficiently managed centrally wi...
github.com
February 23, 2024 at 5:18 PM
asn - Network recon tool
🚀 v.0.76.0 release AS target lookup improvements:
⚡ Accelerate pWhois for AS OrgIDs & INETNUMs
🔍 Faster INETNUM origin lookup via Team Cymru WHOIS
🚥 Highlight unannounced INETNUMs
🔄 Switched to RIPEStat API
#osint #shodan #infosec #cybersecurity
GitHub - nitefood/asn: ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web tr...
ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server - ni...
github.com
February 22, 2024 at 1:44 PM
Trufflehog - credentials scanner v.3.68.0 release update
- Added canary detection without detonation
#securitytools #infosec #cybersecruity
trufflesecurity.com
Truffle Security Co.
Truffle Security is an open-source security software company that secures sensitive data by detecting and remediating leaked keys and credentials.
trufflesecurity.com
February 21, 2024 at 6:46 PM
Authentik - Identity Provider focused on flexibility and versatility release 2024.2.0
- fix for webauthn retry
- fixed rbac in permission_required decorator
#securitytools #idp #sso #infosec #cybersecurity
Welcome | authentik
Bring all of your authentication into a unified platform.
goauthentik.io
February 21, 2024 at 6:35 PM
Artemis - security vulnerability scanner developed by CERT PL v2.6.0 release
- Finding selected Nuclei vulnerabilities
- WordPress plugin version check
- Added Known Exploited Vulnerabilities KEV source
#securitytools #infosec #cybersecurity
The Artemis security scanner
Artemis is an open-source security vulnerability scanner developed by CERT PL. It is built to look for website misconfigurations and vulnerabilities on a large number of sites. It automatically prepar...
cert.pl
February 21, 2024 at 6:05 PM
Cloudlist - listing assets from multi cloud v1.0.7 release update
- added integration with Kubernetes via config block. Specify connection details via file path or encoded kubeconfig. Priority to kubeconfig_encoded if both are provided.
#devops #k8s #infosec #cybersecurity
GitHub - projectdiscovery/cloudlist: Cloudlist is a tool for listing Assets from multiple Cloud Providers.
Cloudlist is a tool for listing Assets from multiple Cloud Providers. - projectdiscovery/cloudlist
github.com
February 21, 2024 at 1:32 PM
Copacetic - Quickly patch containers for security without full rebuilds. Copa addresses operational gaps, enabling non-publishers like DevSecOps to patch images.
project-copacetic.github.io/copacetic/we...
#securitytools #vulnerabilities #infosec #cybersecurity
February 20, 2024 at 10:15 PM
Security Onion - Threat hunting and security monitoring platform 2.4.50 release
- IKE pipeline
- DoD Stig compliance
- Integrations for Citrix, Nginx Winlog, RITA Logs
- Improved co-relations in SOC
#securitytools #ids #infosec #cybersecurity
blog.securityonion.net/2024/02/secu...
Security Onion 2.4.50 now available including some new features and lots of bug fixes!
Security Onion 2.4.50 is now available! It includes some new features for our fellow defenders and lots of bug fixes! https://docs.securityo...
blog.securityonion.net
February 20, 2024 at 8:05 PM